CVE Tools

Adobe Commerce Bug Targeted Immediately After Disclosure

SecurityWeekBy Ionut Arghire

PatchAdobe CommerceMagento Open Source

Our summary

Adobe has released a security update to address CVE-2026-71362, a critical authorization flaw affecting Adobe Commerce and Magento Open Source that was rapidly targeted following its public disclosure. With a CVSS score of 9.1, this vulnerability allows unauthenticated remote attackers to hijack customer sessions and access private data by switching account identities. Although Adobe reported no prior in-the-wild exploitation before the advisory, security firm Sansec confirmed they intercepted initial exploitation attempts shortly after the bug was made public. The fix modifies how customer identity is handled in sessions and applies to all versions up to and including the July 2026 patches.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store